Boletines de Vulnerabilidades

IBM Security Bulletin: Security vulnerabilities in Node.js modules affect IBM Business Process Manager (BPM) Configuration Editor (CVE-2014-6394, CVE-2014-7191)


Información sobre el sistema

   
Software afectado IBM

Descripción

Security vulnerabilities have been reported for some dependent Node.js modules. IBM Business Process Manager includes a stand-alone tool for editing configuration properties files that is based on open source Node.js technology. CVE(s): CVE-2014-6394 and CVE-2014-7191 Affected product(s) and affected version(s): IBM Business Process Manager Express V8.5.5 IBM Business Process Manager Standard V8.5.5 IBM Business Process Manager Advanced V8.5.5 Refer to the following reference

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_security_vulnerabilities_in_node_js_modules_affect_ibm_business_process_manager_bpm_configuration_editor_cve_2014_6394_cve_2014_7191?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-6394 ,CVE-2014-7191 ,CVE-2013-2174 ,CVE-2013-4545 ,CVE-2014-0015 ,CVE-2014-0138 ,CVE-2014-2653 ,CVE-2014-0076 and CVE-2014-3566.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-11-07

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT